Every two other week, someone writes that openGPG is broken. Guess what they want to say is that if you use PGP in certain ways, it's broken (keyservers, addons like enigmail and so on). But nobody has ever been able to demonstrate that it's broken if you use it correctly. I'll stick with openGPG.
Cryptography Dispatches: Hello World, and OpenPGP Is Broken
61–70 of 72 posts
Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken
#62Every two other week, someone writes that openGPG is broken. Guess what they want to say is that if you use PGP in certain ways, it's broken (keyservers, addons like enigmail and so on). But nobody has ever been able to demonstrate that it's broken if you use it correctly. I'll stick with openGPG.
Is that a fork of openPGP or some other product that is based on the same specs? I could not find anything meaningful for openGPG.
It's another product based on the same specs.
Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken
#63Can we stop saying that pgp is busted and just talk about how the keyservers are the problem with how people decides to exchange keys ? I don't use key servers. So when I get an encrypted message from my friend I have no issues. Allowing a third party such as a key server to play some role in veifiing the authenticity of a key is basically broken from tht start, and has nothing to do with pgp it's self.
Well, I always ignore the more grandiose claims - since there is currently no alternative for GPG, and installing Electron apps for Signal or Wire (which then use a single centralized server) really isn’t a viable GPG alternative But even if you don’t agree with the argument that federation is dead and we truly need Electron apps (with eternally outdated Chrome instances) for secure communication, still you have to a…
Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken
#64Every two other week, someone writes that openGPG is broken. Guess what they want to say is that if you use PGP in certain ways, it's broken (keyservers, addons like enigmail and so on). But nobody has ever been able to demonstrate that it's broken if you use it correctly. I'll stick with openGPG.
Is that a fork of openPGP or some other product that is based on the same specs? I could not find anything meaningful for openGPG.
Maybe you're thinking of https://sequoia-pgp.org/ or https://neopg.io/ ?
Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken
#65Earlier quoted context omitted.
What do you use for secure communication in lieu of openpgp?
Signal or Wire, magic-wormhole. The obvious stuff.
Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken
#66> I don’t believe in invasive tracking And yet, I see 'utm_source=cryptography-dispatches' in the URLs!
Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken
#67Earlier quoted context omitted.
> Both of those statements are false. Pop on over to wikipeida, you will how wrong you actually are. >> "Signal uses standard cellular mobile numbers as identifiers" >> "The applications include mechanisms by which users can independently verify >> the identity of their messaging correspondents and the integrity of the data >> channel." That is what I described, its trust us first, and maybe verify later if you think…
This is just a series of non-sequiturs.
Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken
#68Earlier quoted context omitted.
PGP is a protocol, there is nothing wrong with it. If you want to complain about good PGP based apps that is a entirely different argument (and it think that is what you are arguing). Signal is not a protocol, it is a application. It uses open whisper (or some mutation of it) as its underlying protocol. That being said, you are still relying on trust provided by the signal servers that they properly authenticated you…
Both of those statements are false. There are clear things wrong with the PGP protocol. PGP predates authenticated encryption (let alone modern AEAD ciphers) and the hacks PGP came up with to authenticate ciphertext resulted both in stripping attacks and, indirectly, in the Efail attack from last year. It was also Signal's linear packet based key format that resulted in the GnuPG/SKS attacks. Signal is a protocol; in…
Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken
#69Earlier quoted context omitted.
Signal or Wire, magic-wormhole. The obvious stuff.
Would you happen to know if you can send stuff using Signal to someone whose phone is offline? You do seem to be able to do it using Wire but I would rather avoid it as the device verification seems broken.
Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken
#70I've mostly been able to avoid PGP, but one workflow that I haven't been able to find a decent alternative for it Git commit signing. Does anyone know good alternatives in this space?
Linus himself has expressed his opinion several times that signing every commit is useless. His posts here explain it a bit: http://git.661346.n2.nabble.com/GPG-signing-for-git-commit-t...